arrow
Return

Malware Clustering Using Family Dependency Graph

delete2019-01-01
delete4
delete
OA
AI
B
Binlin Cheng
Q
Qiang Tong *
W
Wang Jian-hong
W
Wenhui Tian
DOI:10.1109/ACCESS.2019.2914031delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Malware brings a major security threat on the Internet today. It is not surprising that much research has concentrated on detecting malware. Unfortunately, the current malware detection approaches suffer from ineffective detection of new malware samples. These models effectively identify the known malware samples but not new variants. To address this issue, we propose a novel malware detection approach based on the family graph. First, we trace the API calls of the monitored application, and then we generate the dependency graph based on the dependency relationship of the API calls. At last, we construct the family dependency graph via clustering the graphs of a known malware family. In this way, we can determine whether a new sample belongs to a known malware family. The evaluation results show that our approach is effective with small overhead compared to other existing approaches.
Keywords:
Malware
dynamic analysis
API call
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

IEEE Access cover
IEEE Access
IF:
3.6
Papers:
9.8W
Citations:
29.4W

Organization

H
hubei normal university
Scholars:
2.5K
Papers: 1.6K
Citations: 2